← All frameworks
International INTERNATIONAL · Operational Technology · SA

NCA OTCC

NCA Operational Technology Cybersecurity Controls (OTCC-1:2022)

OTCC-1:2022

47 controls · 23 domains · 122 sub-controls
Start assessment in platform →

About this framework

OTCC is Saudi Arabia's mandatory cybersecurity standard for operational technology, the control systems that run power, water, oil and gas, and industrial plants. Issued by the National Cybersecurity Authority, it extends the ECC controls across 23 subdomains for OT environments.

Who needs this

Mandatory for Saudi operators of operational technology in energy, utilities, oil and gas, and manufacturing.

Cross-framework coverage

Controls in NCA OTCC also cover:

NCA ECC-2 22 shared
Qatar NIA 21 shared
UAE IA 21 shared
ADHICS 20 shared
ISO 27001 20 shared

See how NCA OTCC connects to the rest → the Security Universe

Control domains

1-1 · Cybersecurity Policies and Procedures 3
1-1-1
Cybersecurity Policies and Procedures — 1-1-1
Do you have documented, approved OT/ICS cybersecurity policies and procedures, reviewed periodically and aligned to NCA/ECC requirements?
OT/ICS cybersecurity policy set; approval & version history; periodic-review records.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-1-2
Cybersecurity Policies and Procedures — 1-1-2
Do you have documented, approved OT/ICS cybersecurity policies and procedures, reviewed periodically and aligned to NCA/ECC requirements?
OT/ICS cybersecurity policy set; approval & version history; periodic-review records.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-1-3
Cybersecurity Policies and Procedures — 1-1-3
Do you have documented, approved OT/ICS cybersecurity policies and procedures, reviewed periodically and aligned to NCA/ECC requirements?
OT/ICS cybersecurity policy set; approval & version history; periodic-review records.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-2 · Cybersecurity Roles and Responsibilities 1
1-2-1
Cybersecurity Roles and Responsibilities — 1-2-1
Are OT/ICS cybersecurity roles and responsibilities defined and assigned (incl. governance and operations)?
RACI / roles matrix; appointment letters; org chart showing OT security ownership.
2 sub-controls
  • 1-2-1-1 1-2-1-1
  • 1-2-1-2 1-2-1-2
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-3 · Cybersecurity Risk Management 1
1-3-1
Cybersecurity Risk Management — 1-3-1
Is there an OT/ICS cybersecurity risk management methodology, with risk assessments performed and treated?
OT risk methodology; risk register/assessments; treatment plans & owners.
7 sub-controls
  • 1-3-1-1 1-3-1-1
  • 1-3-1-2 1-3-1-2
  • 1-3-1-3 1-3-1-3
  • 1-3-1-4 1-3-1-4
  • 1-3-1-5 1-3-1-5
  • 1-3-1-6 1-3-1-6
  • 1-3-1-7 1-3-1-7
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
1-4 · Cybersecurity in Industrial Control System Project Management 2
1-4-1
Cybersecurity in Industrial Control System Project Management — 1-4-1
Are cybersecurity requirements embedded in OT/ICS project management (new systems, expansions, migrations)?
Project security requirements checklist; secure design/acceptance gates; sample project records.
4 sub-controls
  • 1-4-1-1 1-4-1-1
  • 1-4-1-2 1-4-1-2
  • 1-4-1-3 1-4-1-3
  • 1-4-1-4 1-4-1-4
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-4-2
Cybersecurity in Industrial Control System Project Management — 1-4-2
Are cybersecurity requirements embedded in OT/ICS project management (new systems, expansions, migrations)?
Project security requirements checklist; secure design/acceptance gates; sample project records.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-5 · Cybersecurity in Change Management 4
1-5-1
Cybersecurity in Change Management — 1-5-1
Are cybersecurity requirements embedded in OT/ICS change management, with controlled, tested changes?
Change management procedure; change tickets/CAB approvals for OT; rollback/test evidence.
UAE IAQatar NIAISO 27001NCA CCCNCA ECC-2PCI DSS 4.0.1
1-5-2
Cybersecurity in Change Management — 1-5-2
Are cybersecurity requirements embedded in OT/ICS change management, with controlled, tested changes?
Change management procedure; change tickets/CAB approvals for OT; rollback/test evidence.
UAE IAQatar NIAISO 27001NCA CCCNCA ECC-2PCI DSS 4.0.1
1-5-3
Cybersecurity in Change Management — 1-5-3
Are cybersecurity requirements embedded in OT/ICS change management, with controlled, tested changes?
Change management procedure; change tickets/CAB approvals for OT; rollback/test evidence.
5 sub-controls
  • 1-5-3-1 1-5-3-1
  • 1-5-3-2 1-5-3-2
  • 1-5-3-3 1-5-3-3
  • 1-5-3-4 1-5-3-4
  • 1-5-3-5 1-5-3-5
UAE IAQatar NIAISO 27001NCA CCCNCA ECC-2PCI DSS 4.0.1
1-5-4
Cybersecurity in Change Management — 1-5-4
Are cybersecurity requirements embedded in OT/ICS change management, with controlled, tested changes?
Change management procedure; change tickets/CAB approvals for OT; rollback/test evidence.
UAE IAQatar NIAISO 27001NCA CCCNCA ECC-2PCI DSS 4.0.1
1-6 · Periodical Cybersecurity Review and Audit 2
1-6-1
Periodical Cybersecurity Review and Audit — 1-6-1
Are OT/ICS cybersecurity controls reviewed and audited periodically for compliance?
Review/audit schedule; internal/external audit reports; corrective-action tracker.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-6-2
Periodical Cybersecurity Review and Audit — 1-6-2
Are OT/ICS cybersecurity controls reviewed and audited periodically for compliance?
Review/audit schedule; internal/external audit reports; corrective-action tracker.
CJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
1-7 · Cybersecurity in Human Resources 2
1-7-1
Cybersecurity in Human Resources — 1-7-1
Are OT/ICS personnel cybersecurity risks managed before, during and after employment?
Screening for OT roles; security clauses in contracts; access revocation on exit.
NCA ECC-2NIS2Qatar NIAUAE IAADHICSISO 27001NCA CCCPCI DSS 4.0.1SAMA CSF
1-7-2
Cybersecurity in Human Resources — 1-7-2
Are OT/ICS personnel cybersecurity risks managed before, during and after employment?
Screening for OT roles; security clauses in contracts; access revocation on exit.
NCA ECC-2NIS2Qatar NIAUAE IAADHICSISO 27001NCA CCCPCI DSS 4.0.1SAMA CSF
1-8 · Cybersecurity Awareness and Training Program 2
1-8-1
Cybersecurity Awareness and Training Program — 1-8-1
Do OT/ICS staff and relevant third parties receive role-appropriate cybersecurity awareness and training?
OT awareness programme & schedule; attendance records; role-based training material.
CJISADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
1-8-2
Cybersecurity Awareness and Training Program — 1-8-2
Do OT/ICS staff and relevant third parties receive role-appropriate cybersecurity awareness and training?
OT awareness programme & schedule; attendance records; role-based training material.
2 sub-controls
  • 1-8-2-1 1-8-2-1
  • 1-8-2-2 1-8-2-2
CJISADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
2-1 · Asset Management 2
2-1-1
Asset Management — 2-1-1
Do you maintain an accurate, detailed OT/ICS asset inventory (incl. classification and ownership)?
OT/ICS asset inventory; classification scheme; assigned asset owners.
5 sub-controls
  • 2-1-1-1 2-1-1-1
  • 2-1-1-2 2-1-1-2
  • 2-1-1-3 2-1-1-3
  • 2-1-1-4 2-1-1-4
  • 2-1-1-5 2-1-1-5
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-1-2
Asset Management — 2-1-2
Do you maintain an accurate, detailed OT/ICS asset inventory (incl. classification and ownership)?
OT/ICS asset inventory; classification scheme; assigned asset owners.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-2 · Identity and Access Management 2
2-2-1
Identity and Access Management — 2-2-1
Is OT/ICS identity & access management enforced — least privilege, MFA where feasible, segregation, no shared accounts?
Access control procedure; privileged-access register; access-review records; MFA config.
11 sub-controls
  • 2-2-1-1 2-2-1-1
  • 2-2-1-2 2-2-1-2
  • 2-2-1-3 2-2-1-3
  • 2-2-1-4 2-2-1-4
  • 2-2-1-5 2-2-1-5
  • 2-2-1-6 2-2-1-6
  • 2-2-1-7 2-2-1-7
  • 2-2-1-8 2-2-1-8
  • 2-2-1-9 2-2-1-9
  • 2-2-1-10 2-2-1-10
  • 2-2-1-11 2-2-1-11
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
2-2-2
Identity and Access Management — 2-2-2
Is OT/ICS identity & access management enforced — least privilege, MFA where feasible, segregation, no shared accounts?
Access control procedure; privileged-access register; access-review records; MFA config.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
2-3 · System and Processing Facilities Protection 2
2-3-1
System and Processing Facilities Protection — 2-3-1
Are OT/ICS systems and processing facilities (workstations, servers, SIS) hardened and protected against cyber risk?
Hardening baselines; SIS protection measures; removable-media & malware controls; config records.
13 sub-controls
  • 2-3-1-1 2-3-1-1
  • 2-3-1-2 2-3-1-2
  • 2-3-1-3 2-3-1-3
  • 2-3-1-4 2-3-1-4
  • 2-3-1-5 2-3-1-5
  • 2-3-1-6 2-3-1-6
  • 2-3-1-7 2-3-1-7
  • 2-3-1-8 2-3-1-8
  • 2-3-1-9 2-3-1-9
  • 2-3-1-10 2-3-1-10
  • 2-3-1-11 2-3-1-11
  • 2-3-1-12 2-3-1-12
  • 2-3-1-13 2-3-1-13
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusISO 27001NCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIAUAE IADORAGDPR (EU)HIPAA Security RuleNIS2PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021SAMA CSFUK GDPR
2-3-2
System and Processing Facilities Protection — 2-3-2
Are OT/ICS systems and processing facilities (workstations, servers, SIS) hardened and protected against cyber risk?
Hardening baselines; SIS protection measures; removable-media & malware controls; config records.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusISO 27001NCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIAUAE IADORAGDPR (EU)HIPAA Security RuleNIS2PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021SAMA CSFUK GDPR
2-4 · Network Security Management 2
2-4-1
Network Security Management — 2-4-1
Is the OT/ICS network secured — segmentation/zoning, secure interconnections, IDS/monitoring, and isolation from IT/internet?
Network architecture/zoning diagram (IEC 62443 zones & conduits); firewall/DMZ rules; segregation evidence.
16 sub-controls
  • 2-4-1-1 2-4-1-1
  • 2-4-1-2 2-4-1-2
  • 2-4-1-3 2-4-1-3
  • 2-4-1-4 2-4-1-4
  • 2-4-1-5 2-4-1-5
  • 2-4-1-6 2-4-1-6
  • 2-4-1-7 2-4-1-7
  • 2-4-1-8 2-4-1-8
  • 2-4-1-9 2-4-1-9
  • 2-4-1-10 2-4-1-10
  • 2-4-1-11 2-4-1-11
  • 2-4-1-12 2-4-1-12
  • 2-4-1-13 2-4-1-13
  • 2-4-1-14 2-4-1-14
  • 2-4-1-15 2-4-1-15
  • 2-4-1-16 2-4-1-16
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusNCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIAUAE IAISO 27001
2-4-2
Network Security Management — 2-4-2
Is the OT/ICS network secured — segmentation/zoning, secure interconnections, IDS/monitoring, and isolation from IT/internet?
Network architecture/zoning diagram (IEC 62443 zones & conduits); firewall/DMZ rules; segregation evidence.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusNCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIAUAE IAISO 27001
2-5 · Mobile Devices Security 2
2-5-1
Mobile Devices Security — 2-5-1
Are mobile/portable devices (laptops, handheld configuration & test devices) used in OT environments secured?
Mobile device policy; portable-device controls; data-handling rules for OT field devices.
5 sub-controls
  • 2-5-1-1 2-5-1-1
  • 2-5-1-2 2-5-1-2
  • 2-5-1-3 2-5-1-3
  • 2-5-1-4 2-5-1-4
  • 2-5-1-5 2-5-1-5
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRDORANCA CCC
2-5-2
Mobile Devices Security — 2-5-2
Are mobile/portable devices (laptops, handheld configuration & test devices) used in OT environments secured?
Mobile device policy; portable-device controls; data-handling rules for OT field devices.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRDORANCA CCC
2-6 · Data and Information Protection 2
2-6-1
Data and Information Protection — 2-6-1
Is OT/ICS data and information protected for confidentiality, integrity and availability per policy and law?
Data classification & handling procedures; integrity controls; data protection evidence.
4 sub-controls
  • 2-6-1-1 2-6-1-1
  • 2-6-1-2 2-6-1-2
  • 2-6-1-3 2-6-1-3
  • 2-6-1-4 2-6-1-4
ADHICSCJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCCHIPAA Security RuleNIS2SAMA CSF
2-6-2
Data and Information Protection — 2-6-2
Is OT/ICS data and information protected for confidentiality, integrity and availability per policy and law?
Data classification & handling procedures; integrity controls; data protection evidence.
ADHICSCJISCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCCHIPAA Security RuleNIS2SAMA CSF
2-7 · Cryptography 2
2-7-1
Cryptography — 2-7-1
Are cryptographic controls applied appropriately in the OT/ICS environment (where they don't impair safety/availability)?
Cryptography standard for OT; key management; encryption-in-transit/at-rest evidence.
UAE IACJISADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPR
2-7-2
Cryptography — 2-7-2
Are cryptographic controls applied appropriately in the OT/ICS environment (where they don't impair safety/availability)?
Cryptography standard for OT; key management; encryption-in-transit/at-rest evidence.
UAE IACJISADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPR
2-8 · Backup and Recovery Management 2
2-8-1
Backup and Recovery Management — 2-8-1
Are OT/ICS backups taken, protected and recovery-tested to restore operations after disruption?
Backup policy & schedule for OT configs/data; restore-test results; offline/immutable backup evidence.
4 sub-controls
  • 2-8-1-1 2-8-1-1
  • 2-8-1-2 2-8-1-2
  • 2-8-1-3 2-8-1-3
  • 2-8-1-4 2-8-1-4
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
2-8-2
Backup and Recovery Management — 2-8-2
Are OT/ICS backups taken, protected and recovery-tested to restore operations after disruption?
Backup policy & schedule for OT configs/data; restore-test results; offline/immutable backup evidence.
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
2-9 · Vulnerabilities Management 2
2-9-1
Vulnerabilities Management — 2-9-1
Is OT/ICS vulnerability management performed (identification, assessment, risk-based remediation) without disrupting operations?
Vulnerability management procedure; OT-safe scan results/passive discovery; remediation tracker.
3 sub-controls
  • 2-9-1-1 2-9-1-1
  • 2-9-1-2 2-9-1-2
  • 2-9-1-3 2-9-1-3
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
2-9-2
Vulnerabilities Management — 2-9-2
Is OT/ICS vulnerability management performed (identification, assessment, risk-based remediation) without disrupting operations?
Vulnerability management procedure; OT-safe scan results/passive discovery; remediation tracker.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
2-10 · Penetration Testing 2
2-10-1
Penetration Testing — 2-10-1
Is OT/ICS penetration testing conducted safely and periodically by qualified testers?
Pen-test scope & schedule; OT-safe testing rules of engagement; test reports & remediation.
4 sub-controls
  • 2-10-1-1 2-10-1-1
  • 2-10-1-2 2-10-1-2
  • 2-10-1-3 2-10-1-3
  • 2-10-1-4 2-10-1-4
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
2-10-2
Penetration Testing — 2-10-2
Is OT/ICS penetration testing conducted safely and periodically by qualified testers?
Pen-test scope & schedule; OT-safe testing rules of engagement; test reports & remediation.
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
2-11 · Cybersecurity Event Logs and Monitoring Management 2
2-11-1
Cybersecurity Event Logs and Monitoring Management — 2-11-1
Are OT/ICS cybersecurity event logs collected, monitored and retained (with time sync and protection)?
Logging standard; centralised log/SIEM coverage for OT; retention & time-sync config; monitoring records.
10 sub-controls
  • 2-11-1-1 2-11-1-1
  • 2-11-1-2 2-11-1-2
  • 2-11-1-3 2-11-1-3
  • 2-11-1-4 2-11-1-4
  • 2-11-1-5 2-11-1-5
  • 2-11-1-6 2-11-1-6
  • 2-11-1-7 2-11-1-7
  • 2-11-1-8 2-11-1-8
  • 2-11-1-9 2-11-1-9
  • 2-11-1-10 2-11-1-10
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-11-2
Cybersecurity Event Logs and Monitoring Management — 2-11-2
Are OT/ICS cybersecurity event logs collected, monitored and retained (with time sync and protection)?
Logging standard; centralised log/SIEM coverage for OT; retention & time-sync config; monitoring records.
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-12 · Cybersecurity Incident and Threat Management 2
2-12-1
Cybersecurity Incident and Threat Management — 2-12-1
Is OT/ICS cybersecurity incident and threat management in place (detection, response, reporting to NCA)?
Incident response plan covering OT; CSIRT/contacts; classification scheme; NCA reporting evidence; exercise reports.
8 sub-controls
  • 2-12-1-1 2-12-1-1
  • 2-12-1-2 2-12-1-2
  • 2-12-1-3 2-12-1-3
  • 2-12-1-4 2-12-1-4
  • 2-12-1-5 2-12-1-5
  • 2-12-1-6 2-12-1-6
  • 2-12-1-7 2-12-1-7
  • 2-12-1-8 2-12-1-8
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-12-2
Cybersecurity Incident and Threat Management — 2-12-2
Is OT/ICS cybersecurity incident and threat management in place (detection, response, reporting to NCA)?
Incident response plan covering OT; CSIRT/contacts; classification scheme; NCA reporting evidence; exercise reports.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
2-13 · Physical Security 2
2-13-1
Physical Security — 2-13-1
Is physical security of OT/ICS facilities and equipment enforced (access control, monitoring, environmental)?
Physical access controls & logs; CCTV/monitoring; environmental controls for OT areas.
9 sub-controls
  • 2-13-1-1 2-13-1-1
  • 2-13-1-2 2-13-1-2
  • 2-13-1-3 2-13-1-3
  • 2-13-1-4 2-13-1-4
  • 2-13-1-5 2-13-1-5
  • 2-13-1-6 2-13-1-6
  • 2-13-1-7 2-13-1-7
  • 2-13-1-8 2-13-1-8
  • 2-13-1-9 2-13-1-9
ADHICSHIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
2-13-2
Physical Security — 2-13-2
Is physical security of OT/ICS facilities and equipment enforced (access control, monitoring, environmental)?
Physical access controls & logs; CCTV/monitoring; environmental controls for OT areas.
ADHICSHIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
3-1 · Business Continuity Management (BCM) 2
3-1-1
Business Continuity Management (BCM) — 3-1-1
Is OT/ICS business continuity managed — BIA, continuity/recovery plans, and tested resilience?
Business Impact Analysis; OT continuity & recovery plans (RTO/RPO); continuity test results.
6 sub-controls
  • 3-1-1-1 3-1-1-1
  • 3-1-1-2 3-1-1-2
  • 3-1-1-3 3-1-1-3
  • 3-1-1-4 3-1-1-4
  • 3-1-1-5 3-1-1-5
  • 3-1-1-6 3-1-1-6
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
3-1-2
Business Continuity Management (BCM) — 3-1-2
Is OT/ICS business continuity managed — BIA, continuity/recovery plans, and tested resilience?
Business Impact Analysis; OT continuity & recovery plans (RTO/RPO); continuity test results.
ADHICSCJISCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
4-1 · Third-Party Cybersecurity 2
4-1-1
Third-Party Cybersecurity — 4-1-1
Are third-party cybersecurity risks managed across OT/ICS hardware/software vendors and service providers?
Third-party security requirements & contracts; vendor risk assessments; monitoring & remote-access controls.
4 sub-controls
  • 4-1-1-1 4-1-1-1
  • 4-1-1-2 4-1-1-2
  • 4-1-1-3 4-1-1-3
  • 4-1-1-4 4-1-1-4
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
4-1-2
Third-Party Cybersecurity — 4-1-2
Are third-party cybersecurity risks managed across OT/ICS hardware/software vendors and service providers?
Third-party security requirements & contracts; vendor risk assessments; monitoring & remote-access controls.
CJISADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR

Ready to assess against NCA OTCC?

Start free trial →

Where to go next

See it priced

Map NCA OTCC on any plan — active frameworks scale by tier.

Pricing →

Talk to us

Book a walkthrough with someone who knows the platform.

Book a walkthrough →